CVE-2026-2235: HGiga|C&Cm@il - SQL Injection
Published Feb 9, 2026
·Updated
C&Cm@il developed by HGiga has a SQL Injection vulnerability, allowing authenticated remote attackers to inject arbitrary SQL commands to read database contents.
Affected Software
1 affected component
Hgiga C&Cm@il
Remediation
Information
Update package olln-base to version 7.0-978 or later.
Event History
Feb 9, 2026
CVE Published
via MITRE·07:17 AM
Data Sourced
via MITRE·07:17 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·08:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-2235?
CVE-2026-2235 has a high severity rating due to its potential for critical data exposure through SQL injection.
2
How do I fix CVE-2026-2235?
To fix CVE-2026-2235, apply proper input validation and parameterized queries to prevent SQL injection attacks.
3
Who is affected by CVE-2026-2235?
CVE-2026-2235 affects users of the HGiga C&Cm@il software that allows authenticated access.
4
What type of vulnerability is CVE-2026-2235?
CVE-2026-2235 is a SQL Injection vulnerability that allows attackers to execute arbitrary SQL commands.
5
Can CVE-2026-2235 be exploited remotely?
Yes, authenticated remote attackers can exploit CVE-2026-2235 to read sensitive database contents.